MEDIABIAS.fyi

Check a claim before you share it

Tactic · Social engineering

Pretexting and urgency

A message that manufactures a deadline so you act before you check: your account will be closed, the payment failed, respond now. Identical in structure to viral misinformation.

Who benefits from me acting in the next five minutes rather than in an hour?

What it looks like

A pretext is a story that explains why you are being contacted. Urgency is the clock attached to it. Together they remove the one thing that reliably protects you, which is the second look.

This sits on a media literacy site rather than a security one because the structure is the same as viral misinformation. Both work by arriving inside a narrow window and closing it. The scam wants a payment before you call the bank; the rumour wants a share before you check the source.

Why it works

Time pressure has been tested directly. Participants given either seven or fifteen seconds per email were significantly worse at telling phishing from legitimate mail under the tighter limit, across every persuasion technique tested.1

The reason this generalises is that snap judgment and considered judgment are genuinely different judgments. In an experiment with 1,635 people, participants made an initial call under seven seconds of time pressure plus a memory load, then were allowed unlimited time to reconsider the same headline. Deliberation reduced belief in false headlines while leaving belief in true ones unchanged — and did so evenly across political groups.2 The failure is not gullibility. It is that you only ever got the first judgment.

And the diffusion evidence shows why the window matters: across roughly 126,000 cascades spread by about three million people, false stories reached 1,500 people about six times faster than true ones.3 The gap between arrival and verification is the whole opportunity.

One thing worth knowing, because it is widely assumed and not well supported: a study of more than 14,000 employees over 15 months found that training delivered at the moment someone fails a simulated phishing test can make them more susceptible rather than less. What worked in that study was employees reporting suspicious messages to each other.4

7s vs 15s

time allowed per email. The tighter limit significantly reduced people’s ability to tell phishing from legitimate mail, across every persuasion technique tested.Auton & Sturman, Information and Computer Security, 28 Oct 2025, n=200

6× faster

the speed at which false stories reached 1,500 people compared with true ones. Automated accounts spread both at the same rate; the difference was human.Vosoughi, Roy & Aral, Science, 9 Mar 2018, ~126,000 cascades

62%

of data breaches involved the human element; social engineering accounted for 16 percent of breaches and pretexting for 6 percent as an initial access vector.Verizon Data Breach Investigations Report 2026, 31,000+ incidents across 145 countries

191,561

phishing and spoofing complaints — the single largest complaint category. Business email compromise was 24,768 complaints but $3.05 billion in losses.FBI Internet Crime Complaint Center, 2025 Annual Report, published 6 Apr 2026

Documented cases

The unpaid toll message, 2024 onward

In April 2024 the FBI’s Internet Crime Complaint Center issued a public alert after more than 2,000 complaints in roughly a month about text messages claiming an outstanding road toll balance, warning of a late fee if it was not paid immediately, and linking to a spoofed state toll site.5 The campaign moved state to state using a near-identical script and was still running the following year.

The pretext is mundane on purpose — a small plausible debt, not a fortune — and the fee is the clock. Nothing about it is technically sophisticated.

A help desk, 2023

In September 2023 attackers reached privileged access at a large hospitality company by calling its IT help desk and impersonating employees to have multi-factor authentication reset. The technique is documented in the MITRE ATT&CK catalogue as characteristic of that group: impersonating IT and help-desk staff to compel password and token resets.6 The company’s own filing put the cost at roughly 100 million dollars.

Worth stating precisely: the company has not itself publicly detailed the initial vector. The help-desk attribution comes from the attackers’ claims, from security vendors and from MITRE, not from the company. We include it because the technique is well documented in general, not because this specific chain is confirmed by the victim.

Move 1 — Stop

What to do about it

  • Treat the deadline as the signal. A real bank, employer or toll authority does not lose the ability to help you in twenty minutes.
  • Never use the contact details inside the message. Close it. Find the number on your card, your bill, or a site you navigated to yourself.
  • For voice and video, hang up and call back on a number you already had. A live face and voice are no longer authentication — see the case on the synthetic media page.
  • Put a deliberate delay before anything irreversible — a payment, a credential, a gift card, a transfer. The second look is a different judgment, and that is the whole finding.
  • Report it rather than just deleting it. In the one large field study we found, collective reporting was the part that demonstrably worked.

Sources

Every figure on this page comes from one of these. Each entry names the publisher, the date and the sample size, so you can check it rather than take our word for it.

  1. Auton, J. & Sturman, D. — "Persuasion under pressure: the influence of time pressure on phishing susceptibility"Information and Computer Security 33(5):845–859 · 28 October 2025 · n=200, 60 emailshttps://www.emerald.com/ics/article/33/5/845/1267929/Persuasion-under-pressure-the-influence-of
  2. Bago, B., Rand, D. G. & Pennycook, G. — "Fake news, fast and slow: Deliberation reduces belief in false (but not true) news headlines"Journal of Experimental Psychology: General · 2020 · n=1,635https://gordonpennycook.com/wp-content/uploads/2020/02/bago-rand-pennycook-2020.pdf
  3. Vosoughi, S., Roy, D. & Aral, S. — "The spread of true and false news online"Science 359(6380):1146–1151 · 9 March 2018 · ~126,000 cascades, ~3 million peoplehttps://doi.org/10.1126/science.aap9559
  4. Lain, D., Kostiainen, K. & Čapkun, S. — "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study"IEEE Symposium on Security and Privacy · 2022 · 14,000+ employees over 15 monthshttps://arxiv.org/abs/2112.07498
  5. FBI Internet Crime Complaint Center — public service announcement on smishing regarding road toll servicesFBI IC3, alert I-041224-PSA · 12 April 2024 · 2,000+ complaints in roughly one monthhttps://www.ic3.gov/PSA/2024/PSA240412
  6. MITRE ATT&CK — group profile G1015MITRE · page updated 31 July 2026 · documents help-desk impersonation to force password and MFA resetshttps://attack.mitre.org/groups/G1015/
  7. Verizon — 2026 Data Breach Investigations ReportVerizon Business · May 2026 · 31,000+ incidents, 22,000+ confirmed breaches, 145 countrieshttps://www.verizon.com/business/resources/reports/dbir/
  8. FBI Internet Crime Complaint Center — 2025 Internet Crime ReportFederal Bureau of Investigation · published 6 April 2026https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

What this page is not sure about

Every page here carries this section. A site that tells you to check its sources should be the first to say where its own evidence is thin.

  • The direct experimental test of time pressure that we cite had 200 participants, mostly undergraduates. It points the same way as the wider literature, and on its own it is thin. We would rather say that than present it as settled.
  • Phishing-simulation vendors publish figures showing large improvements from their own training. We have not cited them. The independent field study we did cite found that badly-timed training can make things worse, which is the less convenient finding and the better-evidenced one.
  • For the help-desk case, the victim company has never confirmed the initial access method. We have said so on the page rather than reporting the widely-repeated version as established fact.